Security advisory #29

Information

State: published
Published at: 2026-08-09 22:27:31 CEST
CVEs: CVE-2026-68480
Name: SRSO Safe-RET interrupt-injection bypass
Summary: English: Kernel information disclosure
Česky: Únik informací z jádra
Description: English: On AMD processors affected by SRSO, an unprivileged process inside a VPS can interrupt the shared kernel's Safe-RET sequence and neutralize its return-prediction protection. Carefully mistrained speculative returns can then disclose host-kernel data across the isolation boundary. Published research demonstrates an arbitrary kernel-memory leak on AMD Zen 2, including locating password-hash data, at a low but repeatable rate. The reviewed technical evidence establishes disclosure rather than memory modification: it does not provide root inside the VPS, root on the node, or control of another VPS. Data belonging to the node or another VPS could nevertheless be exposed if it is present in reachable kernel memory.
Česky: Na procesorech AMD zasažených SRSO může neprivilegovaný proces uvnitř VPS přerušením sekvence Safe-RET ve sdíleném jádře vyřadit ochranu predikce návratů. Vhodně ovlivněné spekulativní návraty pak mohou odhalit data hostitelského jádra přes izolační hranici. Publikovaný výzkum na AMD Zen 2 předvádí pomalý, ale opakovatelný únik libovolné paměti jádra včetně nalezení dat s hashi hesel. Analyzované technické podklady potvrzují únik informací, nikoli změnu paměti: neposkytují root uvnitř VPS, root na node ani ovládnutí jiného VPS. Přesto mohou být odhalena data node nebo jiného VPS, pokud se nacházejí v dosažitelné paměti jádra.
Response: English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.3. Interrupt handling now reconstructs the register state produced by a completed Safe-RET sequence and avoids the unsafe return instruction. Upstream Linux includes the fix in 6.12.102 and later stable releases.
Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.3. Obsluha přerušení nyní obnoví stav registrů odpovídající dokončené sekvenci Safe-RET a vyhne se nebezpečné návratové instrukci. Ve stabilních vydáních Linuxu je oprava obsažena od verze 6.12.102.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-09 05:15:09 CEST 2026-08-09 05:15:39 CEST
node20.prg mitigated 2026-08-09 05:15:20 CEST 2026-08-09 05:15:50 CEST
node21.prg mitigated 2026-08-09 05:15:24 CEST 2026-08-09 05:15:54 CEST
node22.prg mitigated 2026-08-09 05:15:05 CEST 2026-08-09 05:15:35 CEST
node23.prg mitigated 2026-08-09 05:15:51 CEST 2026-08-09 05:16:21 CEST
node24.prg mitigated 2026-08-09 05:15:25 CEST 2026-08-09 05:15:55 CEST
node25.prg mitigated 2026-08-09 05:15:09 CEST 2026-08-09 05:15:39 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-09 05:00:50 CEST 2026-08-09 05:01:20 CEST
node1.pgnd mitigated 2026-08-09 13:47:43 CEST 2026-08-09 13:48:13 CEST
node1.stg mitigated 2026-08-07 19:28:40 CEST 2026-08-07 19:29:10 CEST
node2.stg mitigated 2026-08-07 19:28:40 CEST 2026-08-07 19:29:10 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791